PT-2025-26061 · Linux+4 · Linux Kernel+4

Published

2022-07-18

·

Updated

2025-07-15

·

CVE-2022-50135

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A null pointer dereference issue has been identified in the Linux kernel. The problem occurs when the rxe create qp function calls rxe qp from init, and an error handler sets both scq and rcq to NULL. Subsequently, rxe qp do cleanup is called by rxe put, which directly accesses scq and rcq before checking them, resulting in a null pointer dereference error. The issue arises from the call graph: rxe create qp -> rxe qp from init -> rxe put -> rxe qp do cleanup, where scq and rcq are accessed without prior checks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04570
CESA-2023_2951
CVE-2022-50135
RHSA-2023:2951
RHSA-2023:6583
RHSA-2023_2951
RHSA-2023_6583
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse